Update the CoreDNS ConfigMap in kube-system to add a rewrite rule or a stub zone.
CoreDNS reloads its configuration within seconds without a restart.
Every pod in the cluster then resolves the targeted name to an address of your choosing.
Whether that yields credentials depends on the client.
It needs a listener on the redirected address and a client that does not verify the server certificate against the name it asked for.
Rights needed, any one set:
· any one write verb on the Corefile ConfigMap
· any one write verb on the Corefile ConfigMap
· any one write verb on the Corefile ConfigMap
